OpenAPPA: New Security Engine Achieves 0% Attack Success in Multi-Step Enterprise Workflows

October 4, 2026
OpenAPPA: New Security Engine Achieves 0% Attack Success in Multi-Step Enterprise Workflows
  • OpenAPPA operates outside the agent’s prompt and execution loop, defined by a configuration file (appa.toml) that specifies data sources, audiences, trust levels, and authorities, plus deterministic security enforcement rules.

  • Ablation experiments show that removing remedy plans dramatically lowers task completion, from 89% to 35%, underscoring the importance of recovery mechanisms.

  • The project provides formal algebra and recovery guarantees, with an arXiv publication and a GitHub preview of OpenAPPA, along with comprehensive project documentation.

  • Bench-Corp tested 20 multi-step enterprise workflows, while AgentThreatBench applies the OWASP Top 10 for Agentic Applications; together they evaluate both utility and security.

  • Each tool contract details attributes like requirements, delta restrictions, and effects to enable fine-grained access control—for example, get_ticket_from_crm restricts audiences to internal users, while publish_update requires a public audience.

  • In benchmarks, OpenAPPA achieved 0% attack success with 89% task completion, outperforming Claude Code’s auto mode (10% attack, 90% completion) and Microsoft FIDES (31% attack, 41% completion).

  • The system uses an Agentic Permissions Policy Algebra to label policies for audience and trust, with reading restrictions narrowing audiences and reading unvetted pages lowering trust.

  • OpenAPPA includes recovery semantics: on illegal actions it halts dispatch, offers remediation paths, sanitizes data to expand permitted audiences, and routes requests to human operators for single-action approvals; Disposable Child Branches isolate untrusted reads in transient subagent branches.

  • OpenAPPA, an open-source security engine from Archestra, blocks data exfiltration from prompt injection and model hallucination, released on October 3, 2026.

Summary based on 1 source


Get a daily email with more AI stories

More Stories